CVE-2014-8008
Cisco Unified Communications Manager - Authenticated Absolute Path Traversal via RTMT API
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8008. PoCs published by Bernhard Mueller.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in Cisco Unified Communications Manager, including Shellshock command injection, Local File Inclusion, unauthenticated ping access, and a magic session ID bypass. It provides technical descriptions and example commands but does not include functional exploit code.
Description
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.
Exploits (1)
This advisory details multiple vulnerabilities in Cisco Unified Communications Manager, including Shellshock command injection, Local File Inclusion, unauthenticated ping access, and a magic session ID bypass. It provides technical descriptions and example commands but does not include functional exploit code.